Threat Search: 

ThreatExpert's Statistics for Virus.Win32.PePatch [Ikarus]:

Virus.Win32.PePatch [Ikarus] is also known as:
Threat AliasNumber of Incidents
W32/Autorun-WT [Sophos]13
Trojan-Dropper.Win32.VB.iuj [Kaspersky Lab]8
VirTool:Win32/VBInject.S [Microsoft]7
Packed.Win32.VBCrypt.i [Kaspersky Lab]5
Suspicious.MH690 [Symantec]5
Trojan:Win32/Meredrop [Microsoft]4
Generic Dropper [McAfee]3
Generic.dx [McAfee]3
Trojan.Win32.Vaklik.eop [Kaspersky Lab]2
VirTool:Win32/VBInject.gen!AN [Microsoft]2
Win-Trojan/Bifrose.40960.R [AhnLab]2
Backdoor.Trojan [Symantec]1
Backdoor.Win32.Hupigon.vnd [Kaspersky Lab]1
IRC.Backdoor.Trojan [Symantec]1
Mal/Generic-A [Sophos]1
Trojan.Win32.Vaklik.efe [Kaspersky Lab]1
VirTool:Win32/VBInject.R [Microsoft]1
Virus.Win32.Virut.ce [Kaspersky Lab]1
Virus:Win32/Virut.BM [Microsoft]1
W32.Virut.CF [Symantec]1
W32/Scribble-B [Sophos]1
Win32/Virut.F [AhnLab]1

Virus.Win32.PePatch [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Spain3
Australia1
Belgium1
Germany1

Virus.Win32.PePatch [Ikarus] is known to be created as:
%System%\oembios.exe
%System%\server.exe
%Temp%\ixp000.tmp\fada.exe
%Windir%\config\server.exe
%Windir%\fxstaller.exe
c:\recycler\k-1-3542-4232123213-7676767-8888886\r00t.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.